Vulnerability index

Browse CVEs

109 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Firefox MEDIUM 6.5
CVE-2022-29916

Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to pro…

Fix: 91.9 / 100.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-22745

Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerability affects Firefox ESR < 91…

Fix: 91.5 / 96.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2021-43536

Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thun…

Fix: 91.4.0 / 95.0+
Fix from $1,600 2021-12-08
Firefox HIGH 7.4
CVE-2020-15647

A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data dis…

Fix: 68.10.1+
Fix from $1,950 2020-08-10
Firefox HIGH 7.5
CVE-2020-6830

For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was b…

Fix: 25.0+
Fix from $1,950 2020-05-26
Firefox MEDIUM 5.3
CVE-2020-6812

The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera…

Fix: 68.6.0 / 74.0+
Fix from $1,600 2020-03-25
Firefox MEDIUM 5.3
CVE-2019-17018

When in Private Browsing Mode on Windows 10, the Windows keyboard may retain word suggestions to improve the accuracy of the keyboard. This vulnerabi…

Fix: 72.0+
Fix from $1,600 2020-01-08
Firefox MEDIUM 5.3
CVE-2018-12400

In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows informati…

Fix: 63.0+
Fix from $1,600 2019-02-28
Firefox HIGH 7.1
CVE-2018-12397

A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being…

Fix: 60.3.0 / 63.0+
Fix from $1,950 2019-02-28
Firefox HIGH 7.5
CVE-2018-5134

WebExtensions may use "view-source:" URLs to view local "file:" URL content, as well as content stored in "about:cache", bypassing restrictions that …

Fix: 59.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2018-5137

A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. This script does this by using a…

Fix: 59.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 6.5
CVE-2018-5132

The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allow a mali…

Fix: 59.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.5
CVE-2018-5133

If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this content is not sanitized. It…

Fix: 59.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5140

Image for moz-icons can be accessed through the "moz-icon:" protocol through script in web content even when otherwise prohibited. This could allow f…

Fix: 59.0+
Fix from $1,600 2018-06-11
Firefox HIGH 7.5
CVE-2018-5115

If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed over the currently loaded for…

Fix: after 57.0.4
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5106

Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a user selects error links when…

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5114

If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that document …

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5118

The screenshot images displayed in the Activity Stream page displayed when a new tab is opened is created from the meta tags of websites. An issue wa…

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5119

The reader view will display cross-origin content when CORS headers are set to prohibit the loading of cross-origin content by a site. This could all…

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.5
CVE-2017-7844

A combination of an external SVG image referenced on a page and the coloring of anchor links stored within this image can be used to determine which …

Fix: 57.0.1+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7831

A vulnerability where the security wrapper does not deny access to some exposed properties using the deprecated "_exposedProps_" mechanism on proxy o…

Fix: after 56.0.2
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7842

If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" elements instead of one. One o…

Fix: after 56.0.2
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7808

A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths instead of the o…

Fix: 55.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7812

If web content on a page is dragged onto portions of the browser UI, such as the tab bar, links can be opened that otherwise would not be allowed to …

Fix: after 55.0.3
Fix from $1,600 2018-06-11
Firefox HIGH 7.5
CVE-2017-7759

Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs, allowing for the reading of l…

Fix: 54.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.5
CVE-2017-7768

The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincing the s…

Fix: 52.2.0 / 54.0+
Fix from $1,600 2018-06-11
Firefox HIGH 7.5
CVE-2017-5425

The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access to some da…

Fix: 52.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.5
CVE-2017-5414

The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating systems, this can lead to inform…

Fix: 52.0+
Fix from $1,600 2018-06-11
Firefox HIGH 7.5
CVE-2017-5382

Feed preview for RSS feeds can be used to capture errors and exceptions generated by privileged content, allowing for the exposure of internal inform…

Fix: 51.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-5385

Data sent with in multipart channels, such as the multipart/x-mixed-replace MIME type, will ignore the referrer-policy response header, leading to po…

Fix: 51.0+
Fix from $1,950 2018-06-11